Thread-based sandboxing for untrusted software execution
Abstract
This disclosure describes approaches for sandboxing a thread and memory resources within non-secure/secure processing environments such as in a TrustZone-M processor architecture. An example method of controlling memory access includes: providing a memory locking service in a computing device having a secure processing environment and a non-secure processing environment, and executing the memory locking service in the secure processing environment; receiving a request with the memory locking service to establish a sandbox for a particular thread that executes in the non-secure processing environment and is associated with at least one specified memory region; and associating other threads of the non-secure processing environment with the secure processing environment, such that the particular thread is unable to access memory resources of the other threads while the particular thread is sandboxed.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A method of controlling memory access in a non-secure processing environment, the method comprising:
providing a memory locking service in a computing device, the computing device including a secure processing environment and a non-secure processing environment, wherein the memory locking service is executed in the secure processing environment; receiving a request with the memory locking service to establish a sandbox for a particular thread, the particular thread executing in the non-secure processing environment and associated with at least one specified memory region; and associating other threads of the non-secure processing environment with the secure processing environment, wherein the particular thread is unable to access memory resources of the other threads while the particular thread is sandboxed.
2 . The method of claim 1 , further comprising:
receiving a subsequent request with the memory locking service to remove the sandbox for the particular thread; and re-associating the other threads of the non-secure processing environment with the non-secure processing environment.
3 . The method of claim 2 , wherein the request and the subsequent request are provided from a scheduler of an operating system.
4 . The method of claim 3 , wherein the request and the subsequent request are provided from the scheduler of the operating system, based on an untrusted source of code for the particular thread.
5 . The method of claim 1 , further comprising:
associating resources of an operating system with the secure processing environment, wherein the particular thread is unable to access memory resources of the operating system while the particular thread is sandboxed.
6 . The method of claim 1 , wherein the particular thread is associated with at least one additional memory region for at least one message buffer that is accessible in the non-secure processing environment, and wherein the at least one message buffer is used to communicate data with at least some of the other threads.
7 . The method of claim 1 , wherein the request is received with the memory locking service via an application programming interface, and wherein the application programming interface is configured to receive at least one command to sandbox the particular thread based on a thread identifier.
8 . The method of claim 1 , wherein access to the memory resources for the non-secure processing environment and the secure processing environment is controlled by a Security Attribution Unit and an Implementation Defined Attribution Unit.
9 . A non-transitory machine-readable storage medium comprising instructions, which when executed by processing circuitry of a computing device, causes the processing circuitry to perform operations that:
provide a memory locking service in the computing device, the computing device including a secure processing environment and a non-secure processing environment, wherein the memory locking service is executed in the secure processing environment; receive a request with the memory locking service to establish a sandbox for a particular thread, the particular thread executing in the non-secure processing environment and associated with at least one specified memory region; and associate other threads of the non-secure processing environment with the secure processing environment, wherein the particular thread is unable to access memory resources of the other threads while the particular thread is sandboxed.
10 . The non-transitory machine-readable storage medium of claim 9 , the instructions further to cause the processing circuitry to perform operations that:
receive a subsequent request with the memory locking service to remove the sandbox for the particular thread; and re-associate the other threads of the non-secure processing environment with the non-secure processing environment.
11 . The non-transitory machine-readable storage medium of claim 10 , wherein the request and the subsequent request are provided from a scheduler of an operating system, based on an untrusted source of code for the particular thread.
12 . The non-transitory machine-readable storage medium of claim 9 , the instructions further to cause the processing circuitry to perform operations that:
associate resources of an operating system with the secure processing environment, wherein the particular thread is unable to access memory resources of the operating system while the particular thread is sandboxed.
13 . The non-transitory machine-readable storage medium of claim 9 , wherein the particular thread is associated with at least one additional memory region for at least one message buffer that is accessible in the non-secure processing environment, and wherein the at least one message buffer is used to communicate data with at least some of the other threads.
14 . The non-transitory machine-readable storage medium of claim 9 , wherein the request is received with the memory locking service via an application programming interface, and wherein the application programming interface is configured to receive at least one command to sandbox the particular thread based on a thread identifier.
15 . A computing system, comprising:
memory; a processor configured to provide a non-secure processing environment and a secure processing environment, the secure processing environment to provide a memory locking service; circuitry configured to implement at least one memory protection unit, the at least one memory protection unit to control access to regions of the memory that are associated with the non-secure processing environment or the secure processing environment; and circuitry configured to provide a security attribution unit adapted to:
receive a request with the memory locking service to establish a sandbox for a particular thread, the particular thread executing in the non-secure processing environment and associated with at least one specified memory region; and
associate other threads of the non-secure processing environment with the secure processing environment, wherein the particular thread is unable to access memory resources of the other threads while the particular thread is sandboxed.
16 . The computing system of claim 15 , wherein the circuitry configured to provide the security attribution unit is further adapted to:
receive a subsequent request with the memory locking service to remove the sandbox for the particular thread; and re-associate the other threads of the non-secure processing environment with the non-secure processing environment.
17 . The computing system of claim 16 , wherein the request and the subsequent request are provided from a scheduler of an operating system, based on an untrusted source of code for the particular thread.
18 . The computing system of claim 15 , wherein the circuitry configured to provide the security attribution unit is further adapted to:
associate resources of an operating system with the secure processing environment, wherein the particular thread is unable to access memory resources of the operating system while the particular thread is sandboxed.
19 . The computing system of claim 15 , wherein the particular thread is associated with at least one additional memory region for at least one message buffer that is accessible in the non-secure processing environment, and wherein the at least one message buffer is used to communicate data with at least some of the other threads.
20 . The computing system of claim 15 , wherein the request is received with the memory locking service via an application programming interface, and wherein the application programming interface is configured to receive at least one command to sandbox the particular thread based on a thread identifier.Join the waitlist — get patent alerts
Track US2025384122A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.